Director, Security Research

🏢 Sysdig · all 20 jobs
📍 United States
💰 USD 245,000 - 307,000 / annual
📅 Posted Sep 13, 2026 · via Himalayas
🏷 Security Research, AI Security, Threat Research, Detection Engineering, Cybersecurity Leadership, Security Research Director +5 more
Apply on original site ↗

At Sysdig , we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.
We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.
Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.
If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.
What you will do

You will lead the Sysdig Threat Research Team (TRT). The department has two halves, and you own both. Adversary research is hypothesis-driven and sets its own agenda. Detection engineering is demand-driven and ships the detection content our customers and the Falco community run in production.

We are hiring for AI security research specifically, not threat research generally, and we mean that in both directions. One direction is research into AI-related threats: attacks on models, agents, and the infrastructure they run on. The other is AI-driven research methods, where agents do reproduction, analysis, and detection authoring at a scale people cannot match. We will prioritize candidates who have published original work on AI threats and are already building with AI-driven research methods.

The reach here is unusual, and you inherit real assets. Detection content this team owns ships to Sysdig customers and, through Falco, to everyone running the CNCF project we created. The team's published research is one of the largest drivers of Sysdig 's inbound audience. And the evidence behind that research comes from production telemetry at scale.

- Own Threat Research end-to-end. Set the research agenda, the detection content roadmap, and the budget. You are the final decision-maker on what this team investigates and what it ships.

- Make AI security research the center of gravity. Build a standing capability against model and agent abuse, agentic tool misuse, prompt-layer attacks, the AI supply chain, and attacks on the infrastructure that hosts it all. Turn what you find into a tuned detection, and a blog post.

- Lead a small team of researchers and engineers, hands-on. Set their technical direction, expand what each can cover, and stay close enough to the work to be credible with the people doing it.

- Own the detection content that ships. The managed ruleset, cloud and identity detections, and the quality of all of it. Rule quality is a number this team moves, not a claim it makes.

- Hold our own detections to the standard you would apply to someone else's product. Run adversarial validation against the rules we ship and drive what you find to closure. Coverage and evasion resistance should be engineering measurements, not an annual exercise ending in a PDF.

- Own the detection platform. The toolchain, the attack reproduction environments, behavior-based detection, and adversary-deception telemetry. Build in-house reproduction for every detection family we ship.

- Publish and be the public voice of this work. Original discovery, named campaigns, CVEs, conference stages, and open-source contribution, all resourced and expected. This team's output is one of the most visible things Sysdig produces.

- Partner with Marketing to turn research into content and campaigns that go beyond just the technical write-up.

- Convert research into field capability. Build a library of reusable attack demonstrations, threat briefings, and advisory content, so Sales Engineer

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you